Emergent-Threat CVE Automation
How Guard alerts you when a new high-risk CVE is scanned for, found in your environment, and proven exploitable.
When Praetorian deploys a new detection template for a critical CVE, Guard can notify you in up to three steps: when scanning for the CVE starts, when the CVE is found in your environment, and when a Hannibal hunt proves it is exploitable.
Praetorian turns these notifications on for your account. Contact your Praetorian team to enable them. Accounts without them enabled get Guard's standard new-risk notification when the CVE is found.
Which CVEs qualify
A CVE starts this sequence when its detection template is deployed and the CVE meets either condition:
- It is on the CISA Known Exploited Vulnerabilities list.
- Its EPSS probability is 60% or higher.
The three notifications
1. Security advisory
Guard emails a security advisory when scanning for the CVE starts. The subject is [Praetorian Guard Security Advisory] Critical Vulnerability <CVE ID>. Guard sends it once per CVE.
2. Detection
When the CVE is found on one of your assets as a new open risk, Guard sends Praetorian Guard Emergent Threat Detection instead of the standard new-risk notification. The email subject is [Praetorian Guard] <CVE ID> Detected in Your Environment. The message lists:
- the CVE, its CVSS score and EPSS probability;
- CISA Known Exploited Vulnerability and Public Exploit Available, when they apply;
- the risk, asset, and severity;
- a View Risk link.
Ticketing integrations receive the risk as a regular ticket.
3. Exploitation proven
When the CVE is detected, Guard also tries to start a Hannibal hunt against the finding. The hunt runs for up to 24 hours at aggressive settings. It starts only when:
- AI Autonomy and Automatic Penetration Tests are on (see Automatic Penetration Tests);
- no other hunt is running;
- the account has AI budget headroom.
If the hunt exploits the vulnerability and files evidence, Guard sends Praetorian Guard Emergent Threat — Exploitation Proven. The email subject is [Praetorian Guard] <CVE ID> Exploitation Proven in Your Environment. The message has the same details as the detection notification.